Agent skill

Ag2 Hitl

by ag2ai in ag2ai/build-with-ag2

Pause an AG2 beta Agent mid-run to collect human input via context.input(), or gate a tool call with approvalrequired() middleware.

Apache-2.0Auto-check passed

Install Ag2 Hitl

skills CLI
$ npx skills add ag2ai/build-with-ag2 --skill ag2-hitl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ag2ai/build-with-ag2 ag2-hitl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ag2-hitl .claude/skills/ag2-hitl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ag2-hitl
GitHub stars
252
Token cost
~1.6k tokens
SKILL.md length
479 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Pause an AG2 beta Agent mid-run to collect human input via context.input(), or gate a tool call with approvalrequired() middleware.

  • The user wants the agent to ask for confirmation
  • SKILL.md covers When to use, Pattern 1 — context.input()…, Pattern 2 —… and Pairing both patterns, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Request missing info (passwords

What it does

Ag2 Hitl is an agent skill from ag2ai/build-with-ag2. Pause an AG2 beta Agent mid-run to collect human input via context.input(), or gate a tool call with approvalrequired() middleware. Use when the user wants the agent to ask for confirmation, request missing info (passwords, API keys, data), or have a human approve sensitive / irreversible / expensive tool calls (sending emails, deleting records, payments).

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Sample code and application showcases to get you going with AG2 (formally AutoGen). The licence is Apache-2.0.

When your agent uses it

  • The user wants the agent to ask for confirmation
  • Request missing info (passwords
  • Have a human approve sensitive / irreversible / expensive tool calls (sending emails
  • Deleting records

Example prompts

  • “/ag2-hitl”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 29eeac3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ag2 Hitl loads about 1.6k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 479 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ag2ai/build-with-ag2 at commit 29eeac3, republished under its Apache-2.0 licence (© ag2ai). 479 words, ~1,571 tokens.

Download SKILL.mdSave it as .claude/skills/ag2-hitl/SKILL.md (or your agent's skills folder).
name
ag2-hitl
description
Pause an AG2 beta `Agent` mid-run to collect human input via `context.input()`, or gate a tool call with `approval_required()` middleware. Use when the user wants the agent to ask for confirmation, request missing info (passwords, API keys, data), or have a human approve sensitive / irreversible / expensive tool calls (sending emails, deleting records, payments).
license
Apache-2.0

Human-in-the-loop

When to use

  • The agent should ask for confirmation before doing something risky.
  • The agent needs information from the user mid-conversation (a password, an API key, missing context).
  • A specific tool call should require human approval before it runs (irreversible / expensive / sensitive).
  • Quality assurance — show a draft, get human edits/approval before finalising.

Two distinct mechanisms — pick by intent:

NeedUse
Tool asks an open question and waits for a typed answercontext.input() from inside the tool + hitl_hook on the agent
Approve / deny a specific tool call before its body runsapproval_required() tool middleware

Pattern 1 — context.input() for open questions

A tool requests input via Context.input(prompt, timeout=...). The agent must have a hitl_hook that knows how to collect that input.

python
from autogen.beta import Agent, Context, tool
from autogen.beta.events import HumanInputRequest, HumanMessage

@tool
async def execute_query(context: Context) -> str:
    answer = await context.input(
        "Are you sure you want to run this query? (yes/no)",
        timeout=60.0,
    )
    if answer.strip().lower() != "yes":
        return "Query cancelled."
    return "Query executed successfully."

def hitl_hook(event: HumanInputRequest) -> HumanMessage:
    print(f"Agent asks: {event.content}")
    return HumanMessage(content=input("Your answer: "))

agent = Agent("dba", tools=[execute_query], hitl_hook=hitl_hook)

The hook receives a HumanInputRequest (containing the prompt) and must return a HumanMessage. Both def and async def hooks are supported.

You can also register the hook after construction:

python
agent = Agent("dba", tools=[execute_query])

@agent.hitl_hook
async def async_hitl_hook(event: HumanInputRequest) -> HumanMessage:
    answer = await collect_from_ui(event.content)
    return HumanMessage(content=answer)

The decorator overrides any hook set in the constructor.

The hook participates in dependency injection — Context, Inject, Variable, Depends work the same as in tools.

If context.input() is called and no hook is registered, the framework raises HumanInputNotProvidedError.

Pattern 2 — approval_required() for specific tool calls

Gate a single tool with the built-in approval middleware. The user is prompted before the tool body runs and can approve or deny.

python
from autogen.beta import Agent, tool
from autogen.beta.config import OpenAIConfig
from autogen.beta.middleware import approval_required

@tool(middleware=[approval_required()])
def delete_account(user_id: str) -> str:
    """Deletes a user account by ID permanently."""
    return f"Account {user_id} deleted."

agent = Agent(
    "support",
    config=OpenAIConfig(model="gpt-4o-mini"),
    tools=[delete_account],
    hitl_hook=lambda event: input(event.content),
)

When the agent calls delete_account, the user sees:

Agent tries to call tool:
`delete_account`, {"user_id": "abc-123"}
Please approve or deny this request.
Y/N?

Typing y lets the tool run. Anything else denies it; the agent receives the denial message and can adjust.

approval_required() calls context.input() under the hood, so it also requires a hitl_hook — without one you'll get a runtime error.

Custom prompt
python
@tool(middleware=[approval_required(
    message="⚠️ Run `{tool_name}` with {tool_arguments}? (y/n)",
    denied_message="Operation blocked by user.",
)])
def send_email(to: str, subject: str, body: str) -> str:
    """Send an email to the given address."""
    ...

{tool_name} and {tool_arguments} are interpolated.

Pairing both patterns

For a tool that both gathers input mid-run and requires approval:

python
@tool(middleware=[approval_required()])
async def schedule_report(name: str, context: Context) -> str:
    """Schedule a report — asks the user for the cadence, then runs after approval."""
    cadence = await context.input("How often? (daily / weekly / monthly)")
    return f"Scheduled '{name}' on {cadence} cadence."

The approval middleware runs first (outermost). Once approved, the tool body executes and context.input() triggers a second human interaction.

Show full SKILL.md (176 more words)Show less

Going deeper

  • Source docs: website/docs/beta/context/human_in_the_loop.mdx (context.input, hitl_hook), website/docs/beta/tools/approval_required.mdx (approval_required middleware).
  • Tool middleware in general — website/docs/beta/tools/tool_middleware.mdx. See also ag2-middleware for agent-wide HITL interception via BaseMiddleware.on_human_input().
  • HITL hooks support dependency injection identically to tools — see ../ag2-add-custom-tool/references/dependency_injection.md.

Common pitfalls

  • approval_required() without a hitl_hook — the middleware calls context.input(), so the agent needs a hook. You'll see HumanInputNotProvidedError otherwise.
  • Forgetting to handle the denial path — context.input() returns whatever the hook returns. If you only branch on "yes", any other answer (including silence/default) lets the operation continue. Always validate.
  • Sync input() in an async UI — input() blocks the event loop. Use an async hook (async def) and an async input collector (web socket, message queue) for any non-CLI app.
  • No timeout — context.input(prompt) can wait forever. Pass timeout=60.0 (seconds) for any production path.
  • Decorator hook overrides constructor hook silently — if you set both, the decorator wins. Pick one place.
  • Expecting HumanMessage to flow into the conversation history automatically — it does for the requesting tool's return value, but mid-run inputs collected via ctx.input() are not separate user turns. They live in the tool's scope.

© ag2ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ag2-hitl of ag2ai/build-with-ag2.

Open the folder on GitHubat commit 29eeac3

Compare with similar skills

Ag2 Hitl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ag2 Hitl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ag2 Hitl this skillag2ai/build-with-ag2252—~1.6kAutomated safety check: PassApache-2.0
Collect User Inputdotnet/skills5.6k1 repos~3.2kAutomated safety check: PassMIT
Search Inputthedaviddias/Front-End-Checklist74k—~402Automated safety check: PassMIT
Input Typesthedaviddias/Front-End-Checklist74k—~487Automated safety check: PassMIT
Paste Inputsthedaviddias/Front-End-Checklist74k—~443Automated safety check: PassMIT
Agent Collective Intelligence Coordinatorruvnet/ruflo74k2 repos~1kAutomated safety check: PassMIT

Similar skills

  • Collect User Input

    dotnet/skills

    Official

    Build forms, validate data, and react to user input in Blazor.

    5.6k GitHub starsUsed in 1 repo~3.2k tokens
    DevelopmentAuto-check passed
  • Search Input

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Make search inputs accessible.

    74k GitHub stars~402 tokensUpdated 4 days ago
    Frontend & DesignAuto-check passed
  • Input Types

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Use semantic input type attributes.

    74k GitHub stars~487 tokensUpdated 4 days ago
    Auto-check passed
  • Paste Inputs

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Allow pasting into form inputs.

    74k GitHub stars~443 tokensUpdated 4 days ago
    Frontend & DesignAuto-check passed
  • Agent skill for collective-intelligence-coordinator - invoke with $agent-collective-intelligence-coordinator

    74k GitHub starsUsed in 2 repos~1k tokens
    Auto-check passed
  • Collection Digest

    outline/outline

    Summarize what changed in an Outline collection since a date; use when the user asks what is new, what was updated, or wants a digest of recent documents.

    41k GitHub stars~498 tokensUpdated today
    Knowledge ManagementAuto-check passed

More from ag2ai/build-with-ag2

All 16 skills in this repo
  • Ag2 Add Custom Tool

    ag2ai/build-with-ag2

    Add a custom Python tool to an AG2 beta Agent using the @tool decorator.

    252 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Ag2 Middleware

    ag2ai/build-with-ag2

    Intercept the AG2 beta agent loop with BaseMiddleware — wrap full turns (onturn), each LLM call (onllmcall), each tool execution (ontoolexecution), or each human-input request (onhumaninput).

    252 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Ag2 Use Builtin Tools

    ag2ai/build-with-ag2

    Wire AG2 beta's shipped tools into an Agent — both provider-native server-side tools (web search, web fetch, code execution, MCP, image generation, memory) and locally-executed common toolkits…

    252 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Ag2 Knowledge And Memory

    ag2ai/build-with-ag2

    Persist agent state across runs, shape what the LLM sees per turn, and cap history to fit a context window.

    252 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Ag2 Observers And Alerts

    ag2ai/build-with-ag2

    Monitor an AG2 beta agent's stream — log events, detect repeated tool calls, track token spend, build trigger-driven observers, route observer alerts to the model, and halt on FATAL conditions.

    252 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Ag2 Quickstart

    ag2ai/build-with-ag2

    Build a minimal AG2 beta Agent end to end — pick a model provider, set a prompt, call agent.ask(), then continue the conversation with reply.ask() (multi-turn).

    252 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes

Questions about Ag2 Hitl

What does Ag2 Hitl do?

Pause an AG2 beta Agent mid-run to collect human input via context.input(), or gate a tool call with approvalrequired() middleware. Ag2 Hitl is an agent skill from ag2ai/build-with-ag2.input(), or gate a tool call with approvalrequired() middleware.

When should I use Ag2 Hitl?

Ag2 Hitl fits situations like: the user wants the agent to ask for confirmation; request missing info (passwords; have a human approve sensitive / irreversible / expensive tool calls (sending emails; deleting records.

How do I install Ag2 Hitl in Claude Code?

Run `npx skills add ag2ai/build-with-ag2 --skill ag2-hitl -a claude-code`. Or copy the skill folder (.agents/skills/ag2-hitl in ag2ai/build-with-ag2) into .claude/skills/ag2-hitl in your project. Claude Code loads it when a task matches its description.

How do I install Ag2 Hitl in Codex?

Run `npx skills add ag2ai/build-with-ag2 --skill ag2-hitl -a codex`. Or copy the skill folder (.agents/skills/ag2-hitl in ag2ai/build-with-ag2) into .agents/skills/ag2-hitl in your project. Codex loads it when a task matches its description.

Can I use Ag2 Hitl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ag2ai/build-with-ag2 --skill ag2-hitl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ag2-hitl, .gemini/skills/ag2-hitl, .github/skills/ag2-hitl and .opencode/skills/ag2-hitl in your project.

What does Ag2 Hitl need to run?

SKILL.md names no scripts, command-line tools or credentials: Ag2 Hitl is instructions for the agent only. Our summary lists: Python 3.

Does Ag2 Hitl access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ag2 Hitl safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ag2 Hitl use?

Ag2 Hitl is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ag2 Hitl use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ag2 Hitl?

Skills that share tags, products or a category with Ag2 Hitl: Collect User Input (dotnet/skills, 5.6k stars), Search Input (thedaviddias/Front-End-Checklist, 74k stars), Input Types (thedaviddias/Front-End-Checklist, 74k stars) and Paste Inputs (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ag2 Hitl?

ag2ai (a GitHub organization) maintains it in ag2ai/build-with-ag2, which has 252 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on September 6, 2026.

Source: ag2ai/build-with-ag2 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.